Aon's analysis of over 300 AI disputes exposes a hard truth: when AI systems fail in your firm, your insurance may not cover it—and liability will flow upward to your leadership. This matters desperately to UK law firms, insurers, accountants and financial services businesses because the FCA Consumer Duty (PS22/9), SRA Code, and PRA SS1/23 all now demand *you* own the governance framework, not your AI vendor. The story's claim that AI CEOs should shoulder responsibility for incidents is theoretically sound; the practical problem is that your firm's leadership already bears that responsibility under UK regulation, whether or not the AI vendor's CEO does. Insurance brokers are scrambling to redefine coverage because the old tech E&O buckets—crime, IP, cybersecurity, technology errors—were designed before AI became operational infrastructure inside your business. That gap is live, it is widening, and it is not the vendor's problem to solve.
This story is a symptom of a much larger shift: the industry is moving from 'buy an AI tool and hope' to 'you are liable for how that tool behaves inside your firm.' The vendors selling off-the-shelf solutions—Harvey in legal, Luminance in document review, Microsoft Copilot across financial services—are marketing intelligence and speed. What they cannot sell is accountability. When a general-purpose LLM trained on internet data gives legally incorrect advice to your client, or a black-box classification model wrongly flags a transaction as suspicious, or a document extraction system corrupts your data pipeline, your firm's name is on the problem. The regulatory bodies know this. The ICO UK GDPR guidance on AI processing, the emerging EU AI Act compliance requirements, and Lloyd's Blueprint Two all converge on a single principle: governance is not optional, it is not delegable to your vendor, and it must be documented and auditable. The insurance industry is now pricing this reality into coverage—which means firms that have not yet implemented proper AI governance are walking into a double hit: operational risk AND uninsured liability.
Here is Trovix's view: the difference between a successful AI implementation and a liability nightmare often comes down to *visibility into what your AI is actually doing*. A firm using an off-the-shelf chatbot or document classifier without governance infrastructure in place is flying blind. You have no way to prove to the FCA, the SRA, or a court that the system was used appropriately, that outputs were checked, or that decisions were auditable. The vendors building these tools are solving for feature delivery, not for regulatory defensibility. Trovix Audit exists precisely because mid-market firms need to sit between the vendor's tool and your regulated output—to log what happened, to show who checked what, to prove you met your governance obligations. This is not about distrusting the AI; it is about proving you trusted it responsibly. The firms getting this right are not those picking the flashiest AI product; they are those implementing governance as part of the architecture from day one.
If you have deployed AI in fee-earning or risk decision-making without a formal governance and audit trail, you should treat this as urgent. Start with three concrete steps: first, audit your current AI use—map every system, every input, every decision it influences, every person checking its output. Second, document your governance framework: who approves AI use, how often you validate results, how you handle failures, what your audit trail looks like. Third, engage your insurance broker now—do not wait for an incident to discover your coverage is partial or conditional. UK regulators are moving toward explicit AI governance standards (watch for the FRC's evolving ISA UK guidance on substantive analytical procedures using AI). Your firm's leadership team needs to be able to answer the question: if this AI system made a material error tomorrow, could we prove we managed it responsibly? If the answer is no, you are exposed.
Source: SBS News